Back to skill

Security audit

Split Drive Coach

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-related to partition management, but it needs Review because it uses a silent unverified installer and a broad disk-tool launcher for high-impact system changes.

Only install this after confirming you intentionally want EaseUS Partition Master installed on Windows. Prefer downloading from the vendor manually, inspect publisher/signature details, keep a verified backup before any partition change, and do not run the scripts elevated unless you understand the system-wide disk and installation impact.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install-epm.py:21
Finding

Remote Installer Is Executed Without Integrity or Publisher Verification

Content
View full analysis
bool: for host in ("d1", "d2", "d3"): if output_path.exists(): output_path.unlink() print(f"Trying mirror {host}...") url = f"https://{host}.easeus.com/epm/free/epm_free_ob.exe?source=skills&dest={dest_arg}" try: with urllib.request.urlopen(url, timeout=60) as response, output_path.open("wb") as fh: fh.write(response.read()) if output_path.exists(): return True ``` ```python print("[1/2] Downloading installer...") if not download_installer(dest_arg, dest_path): print("Download failed from all mirrors.") return 1 if not dest_path.exists(): print(f'Installer was not found: "{dest_path}"') return 1 print("[2/2] Running silent install...") proc = subprocess.run( [ str(dest_path), "/verysilent", "/suppressmsgboxes", "/norestart", "/log", ], check=False, ) ``` ### Technical Analysis The script downloads a Windows executable from one of three external mirrors and executes it immediately in silent mode. It only verifies that the destination file exists; it does not verify a cryptographic digest, an Authenticode signature, the expected publisher, the installer version, the response content type, or the final URL after redirects. HTTPS protects the connection in transit under normal conditions, but it does not establish that the retrieved binary is the exact artifact reviewed or approved by the project. The effective executable payload can change independently after the skill package has been audited. A compromised vendor mirror, CDN, signing or relea ...[truncated 1667 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/epm-shellcmd.py:28
Finding

Unrestricted User-Controlled Commands Are Forwarded to Disk-Management Software

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to help split partitions safely, but it also instructs users to run an installer script that downloads and executes external software. Downloading and silently executing a remote binary is a materially different and more dangerous behavior than the declared purpose, introducing supply-chain and remote code execution risk under the guise of a storage-management helper.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to help split partitions safely, but it also instructs users to run an installer script that downloads and executes external software. Downloading and silently executing a remote binary is a materially different and more dangerous behavior than the declared purpose, introducing supply-chain and remote code execution risk under the guise of a storage-management helper.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script exposes a generic launcher for EaseUS Partition Master by mapping the first user argument directly into 'shellcmd' and the rest into 'shellparam', with no allowlist, authorization check, or safety validation. In the context of a skill that is supposed to split large partitions safely, this broader arbitrary command capability could be abused to perform destructive disk operations or other unintended privileged actions through the vendor tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

This wrapper triggers a partition-management executable capable of making destructive system-wide storage changes, yet it provides no confirmation gate, dry-run mode, or explicit warning before launch. Given the skill's system-disk manipulation context, accidental or coerced execution could cause data loss, boot failure, or corruption far beyond the user's apparent intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This file downloads and runs an EaseUS installer, which is unrelated to the declared skill purpose of coaching users on partition splitting. That mismatch strongly suggests hidden secondary behavior, increasing the likelihood that the skill is being used to introduce software rather than perform its stated function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script silently launches a downloaded third-party installer with switches that suppress prompts and messages, causing software installation without meaningful user awareness. In the context of a drive-coaching skill, this behavior is unjustified and can be used to install unwanted or harmful software covertly.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installer is executed with silent flags and no confirmation step, so the user receives no opportunity to review or decline system changes. This creates a high risk of unauthorized software installation and downstream impacts such as persistence, bundled software deployment, or altered system configuration.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs users to run installer and launcher scripts that imply shell execution, network download, and file-writing behavior, yet it declares no explicit tool scope or permissions. This undermines transparency and reviewability, making it easier for a skill to perform sensitive actions without clear user or platform consent boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill repeatedly frames partition splitting as 'without data loss' but does not prominently warn that partition operations inherently modify disk layout and can still cause data loss if interrupted, misconfigured, or run against the wrong target. In this context, overconfident safety framing is especially risky because the skill concerns destructive-capable disk management on a live system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script writes raw user-supplied parameters to a temporary file and never removes it, creating residual sensitive or operational data on disk. If those parameters include drive identifiers, workflow details, or tool directives, other local users or later processes may read or reuse them, and stale files can also lead to accidental replay or forensic leakage.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/epm-shellcmd.py (reported line 55)May include surrounding context.

python
print(r"  C:\Program Files\EaseUS\EaseUS Partition Master\bin\EPMUI.exe")
        return 2

    proc = subprocess.Popen(
        [
            str(epmui_path),
            "startByEpm0",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script embeds a user-controlled destination value into the installer download URL as a query parameter without disclosure or consent. While this is not code execution by itself, it leaks user-supplied data to an external party for tracking or profiling and is unrelated to the stated partitioning purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The script executes a downloaded Windows installer from a temporary directory without any integrity verification, publisher validation, or user approval. Running externally fetched binaries is inherently dangerous because any compromise of the download source, redirect, or file replacement on disk can lead to arbitrary code execution on the host.

Content

Scanner excerpt · scripts/install-epm.py (reported line 54)May include surrounding context.

python
return 1

    print("[2/2] Running silent install...")
    proc = subprocess.run(
        [
            str(dest_path),
            "/verysilent",

Static analysis

No suspicious patterns detected.